On celebration of Joomla! day Bangkok 2010 - a huge Joomla community networking chance, JoomlArt rolls out special 20% OFF promotion program applicable on all JA Joomla products (new purchase only). One coupon used, 15% of total product/membership value will be donated to the event organizer.
All Joomla & JoomlArt fans attend or not attend the event can support Joomla! Day Bangkok. Just buy a Joomla package using coupon code JABANGKOK2010 to enjoy 20% OFF & give 15% to the host. Expires 14 Nov, 2010
DESCRIPTION:
A vulnerability has been reported in the JomSocial component for
Joomla!, which can be exploited by malicious users to compromise a
vulnerable system.
The vulnerability is caused due to the application allowing the
upload of files with arbitrary extensions to a folder inside the
webroot. This can be exploited to execute arbitrary PHP code by
uploading a PHP file.
Successful exploitation of this vulnerability requires that direct
video uploads are enabled and may require that directory listings are
enabled to access the uploaded file.
The vulnerability is reported in version 1.8.8. Prior versions may
also be affected.
SOLUTION:
Reportedly, an update to version 1.8.9 fixes the vulnerability.
PROVIDED AND/OR DISCOVERED BY:
Jeff Channell
ORIGINAL ADVISORY:
JomSocial:
http://www.jomsocial.com/docs/Change_Log#Version_1.8.9